Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
| From: | Rasmus Lerdorf | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-11214@lists.php.net to get a copy of this message | ||
> The chmod function can set the setuid bit on a file that the script has created. Since these
> files are owned by the Web server uid, even in safe mode you can create a setuid copy of /bin/sh
> using a PHP script and then use the setuid shell to access files as the Web server user. I can
> supply my test script upon request.
>
> This issue is a moot point when safe mode is not in effect, since then you can simply exec any
> shell command you want as the Web server uid. Sites that do use safe mode to restrict program
> execution under the Web server uid are more prone to the problem, and then only if they offer
> interactive login access and also have user-writable file systems that allow setuid program
> execution. This is a fairly small set of sites but it's probably nonempty.
>
> Chmod should probably not allow setuid bits when safe mode is in effect.
Hrm, but in safe-mode you can only exec() stuff from the
safe-mode-exec-dir so I am not quite sure how you would launch this setuid
program that you might have managed to create.
Through cgi perhaps? I agree that we probably should have a look at
safe-mode and chmod(), but I don't see a clear exploit here.
-Rasmus